ISC BIND
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*
- >= 9.18.0, <= 9.18.32
- >= 9.20.0, <= 9.20.4
- >= 9.21.0, <= 9.21.3
- >= 9.18.11-S1, <= 9.18.32-S1
A denial-of-service vulnerability has been identified in ISC BIND 9's DNS-over-HTTPS (DoH) implementation. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1. The vulnerability allows clients to exhaust a DNS resolver's CPU and memory by flooding it with crafted valid or invalid HTTP/2 traffic. As a result, the server can become overwhelmed, causing high resource usage and disrupting DoH connections for other clients.
Exploitation of this vulnerability leads to high CPU and memory usage on the affected DNS resolver, causing a denial-of-service condition. This disruption prevents legitimate clients from establishing DNS-over-HTTPS connections, significantly impairing the resolver's performance and availability of the DNS resolution service.
Users can upgrade to BIND 9.18.33, 9.20.5, or 9.21.4. For BIND Supported Preview Edition, upgrade to version 9.18.33-S1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.